Security & Compliance

Built to be trusted

TX2Pay is built on enterprise-grade infrastructure with security at every layer. We protect your business data, your clients' payment information, and your operations — so you can focus on growing your business.

Compliance & certifications

Our compliance posture is built on industry standards. We maintain a continuous program rather than treating compliance as a one-time event.

PCI DSS

SAQ A Compliant
  • Card data is never transmitted to or stored on TX2Pay servers
  • All card tokenization handled by Stripe and Usio (PCI Level 1 processors)
  • Payment pages use hosted or embedded secure fields
  • Annual self-assessment questionnaire (SAQ A) completed
  • No cardholder data environment (CDE) on TX2Pay infrastructure

HIPAA Alignment

Privacy Ready
  • TX2Pay does not process Protected Health Information (PHI) as a covered entity
  • Security practices align with HIPAA administrative, physical, and technical safeguards
  • Data access is role-based and audited
  • Encryption at rest and in transit for all data
  • Business associates (Supabase, AWS, Stripe) maintain HIPAA-eligible agreements

SOC 2

In Progress
  • Controls mapped to SOC 2 Type II Trust Service Criteria
  • Security, Availability, and Confidentiality criteria prioritized
  • Audit logging for all data mutations and access events
  • Formal SOC 2 Type II engagement planned for Q3 2026
  • Penetration testing conducted quarterly

Security controls

Every layer of the TX2Pay stack is secured by design.

Authentication

JWT-based session tokens

Short-lived, cryptographically signed tokens — no persistent sessions stored server-side.

Supabase Auth with MFA support

TOTP-based multi-factor authentication available for all accounts.

Role-based access control

Super-admin, business owner, and staff roles with separate permission scopes.

Data security

Encryption at rest

All database data encrypted at rest using AES-256 on AWS RDS (via Supabase).

TLS 1.2+ in transit

All API traffic and database connections use TLS — no plaintext channels.

Row-Level Security (RLS)

PostgreSQL RLS policies enforce data isolation at the database level — even if application code is bypassed.

Secrets in vault

API keys and sensitive credentials stored in Supabase Vault, not in application config.

Monitoring & audit

Audit logging

All create, update, and delete operations are logged with user ID, IP address, and timestamp.

Rate limiting

Per-IP token-bucket rate limiting on all public endpoints. Graduated tiers: standard, strict, and public.

Edge function logging

All API calls logged with execution time and status. Errors trigger real-time alerts.

Input validation

All incoming data validated with Zod schemas before processing — malformed input is rejected.

Infrastructure

Supabase on AWS

Hosted in AWS us-west-1 (N. California) — SOC 2 Type II, ISO 27001, and PCI DSS Level 1 certified.

Edge functions in Deno

Serverless compute in isolated V8 sandboxes — no shared process memory between tenants.

CDN via Vercel

Frontend served from Vercel's global edge network with automatic HTTPS and DDoS protection.

Backup & recovery

Daily automated backups

Database snapshots taken daily with 30-day retention. Point-in-time recovery available.

Geo-redundant storage

Backups replicated to a secondary AWS region. Data survives regional infrastructure failure.

Tested recovery procedures

Disaster recovery runbooks tested quarterly. RTO target: 4 hours. RPO target: 1 hour.

Incident response

Documented IR plan

Formal incident response plan covering detection, containment, eradication, and recovery phases.

72-hour breach notification

Affected users notified within 72 hours of a confirmed data breach — meeting GDPR and state law requirements.

Security@ contact

Dedicated security contact for vulnerability reports and security inquiries.

Data handling

What we collect, why we collect it, and how long we keep it.

Business data

Account lifetime

Business name, address, contact info, logo. Used to power your account and invoices. Retained for the lifetime of your account.

Client data

Account lifetime

Client names, email addresses, phone numbers, and service history. Used to generate invoices and send payment links. You own this data.

Payment records

7 years (tax/legal)

Invoice amounts, payment dates, and transaction IDs from payment processors. Raw card numbers are never stored.

Usage analytics

12 months

Aggregated feature usage (no PII). Used to improve the product. No third-party advertising tracking.

Security logs

90 days

IP addresses, timestamps, and action types for audit and incident response. Not shared externally.

Email campaign data

Account lifetime

Lead emails, open/click events for campaign analytics. Only for leads you import or create.

Availability commitment

TX2Pay targets 99.9% uptime. Our infrastructure is built on Supabase (AWS) and Vercel, both of which publish their own status pages and uptime SLAs.

99.9%

monthly

Uptime target

4 hrs

after incident

Recovery time objective

1 hr

data loss max

Recovery point objective

Responsible disclosure

If you discover a security vulnerability in TX2Pay, please report it privately. We investigate all reports, aim to respond within 48 hours, and will credit researchers who responsibly disclose issues.

security@tx2pay.com

For general support inquiries, please use our main contact. The security inbox is monitored for vulnerability reports only.